Problèmes ralentissement sérieux
DJ Fab
Messages postés
225
Date d'inscription
Statut
Membre
Dernière intervention
-
DJ Fab Messages postés 225 Date d'inscription Statut Membre Dernière intervention -
DJ Fab Messages postés 225 Date d'inscription Statut Membre Dernière intervention -
Bonjour,
j'ai quelques souci ses dernier jours sur mon PC à des ralentissement assez gênant
rapport Hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:06, on 2009-08-03
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
C:\windows\system32\nvsvc32.exe
C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
C:\windows\Explorer.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\windows\system32\svchost.exe
C:\windows\RTHDCPL.EXE
C:\windows\system32\RUNDLL32.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\BOINC\boinctray.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
C:\windows\system32\ctfmon.exe
C:\windows\System32\svchost.exe
C:\Program Files\BOINC\boinc.exe
C:\Documents and Settings\All Users\Application Data\BOINC\projects\www.worldcommunitygrid.org\wcg_hfcc_autodock_6.10_windows_intelx86
C:\Documents and Settings\All Users\Application Data\BOINC\projects\www.worldcommunitygrid.org\wcg_faah_autodock_6.07_windows_intelx86
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\windows\system32\wuauclt.exe
C:\Documents and Settings\Fabien\Bureau\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ecofree.org/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [boinctray] "C:\Program Files\BOINC\boinctray.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [UberIcon] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [boincmgr] "C:\Program Files\BOINC\boincmgr.exe" /a /s
O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Translate with &Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.line6.net
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{04FA42E3-50E3-45E9-AEB0-8EDA5F8140BA}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\..\{04FA42E3-50E3-45E9-AEB0-8EDA5F8140BA}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS2\Services\Tcpip\..\{04FA42E3-50E3-45E9-AEB0-8EDA5F8140BA}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS3\Services\Tcpip\..\{04FA42E3-50E3-45E9-AEB0-8EDA5F8140BA}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS4\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS4\Services\Tcpip\..\{04FA42E3-50E3-45E9-AEB0-8EDA5F8140BA}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS5\Services\Tcpip\..\{04FA42E3-50E3-45E9-AEB0-8EDA5F8140BA}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS6\Services\Tcpip\..\{04FA42E3-50E3-45E9-AEB0-8EDA5F8140BA}: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: opnmLfGX - C:\windows\
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Google Update Service (gupdate1c98c177460c92a) (gupdate1c98c177460c92a) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
O23 - Service: PD91Agent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
O23 - Service: PD91Engine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
j'ai quelques souci ses dernier jours sur mon PC à des ralentissement assez gênant
rapport Hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:06, on 2009-08-03
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
C:\windows\system32\nvsvc32.exe
C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
C:\windows\Explorer.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\windows\system32\svchost.exe
C:\windows\RTHDCPL.EXE
C:\windows\system32\RUNDLL32.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\BOINC\boinctray.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
C:\windows\system32\ctfmon.exe
C:\windows\System32\svchost.exe
C:\Program Files\BOINC\boinc.exe
C:\Documents and Settings\All Users\Application Data\BOINC\projects\www.worldcommunitygrid.org\wcg_hfcc_autodock_6.10_windows_intelx86
C:\Documents and Settings\All Users\Application Data\BOINC\projects\www.worldcommunitygrid.org\wcg_faah_autodock_6.07_windows_intelx86
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\windows\system32\wuauclt.exe
C:\Documents and Settings\Fabien\Bureau\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ecofree.org/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [boinctray] "C:\Program Files\BOINC\boinctray.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [UberIcon] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [boincmgr] "C:\Program Files\BOINC\boincmgr.exe" /a /s
O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Translate with &Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.line6.net
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{04FA42E3-50E3-45E9-AEB0-8EDA5F8140BA}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\..\{04FA42E3-50E3-45E9-AEB0-8EDA5F8140BA}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS2\Services\Tcpip\..\{04FA42E3-50E3-45E9-AEB0-8EDA5F8140BA}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS3\Services\Tcpip\..\{04FA42E3-50E3-45E9-AEB0-8EDA5F8140BA}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS4\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS4\Services\Tcpip\..\{04FA42E3-50E3-45E9-AEB0-8EDA5F8140BA}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS5\Services\Tcpip\..\{04FA42E3-50E3-45E9-AEB0-8EDA5F8140BA}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS6\Services\Tcpip\..\{04FA42E3-50E3-45E9-AEB0-8EDA5F8140BA}: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: opnmLfGX - C:\windows\
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Google Update Service (gupdate1c98c177460c92a) (gupdate1c98c177460c92a) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
O23 - Service: PD91Agent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
O23 - Service: PD91Engine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
A voir également:
- Problèmes ralentissement sérieux
- Ralentissement pc - Guide
- Tchat voyance gratuit sérieux avis - Forum Vos droits sur internet
- Don de voiture sérieux - Forum Vos droits sur internet
- Sukudrive serieux - Forum Cloud
- Iencheres.com , sérieux? - Forum Réseaux sociaux
27 réponses
Salut Kevin ;)
Je ne vois pas de détournement de DNS ? Les DNS indiquées sur le rapport hijackthis sont légitimes
@ DJ Fab :
Qu'est-ce qui te fait dire que ton ordinateur est encore infecté ? Peux-tu expliquer stp ?
Je ne vois pas de détournement de DNS ? Les DNS indiquées sur le rapport hijackthis sont légitimes
@ DJ Fab :
Qu'est-ce qui te fait dire que ton ordinateur est encore infecté ? Peux-tu expliquer stp ?
ben quand mon ordi met 30 minutes à s'allumer et s'éteindre et quand je veut lire sur une vidéo sur internet ca lag comme pas possible y a un souci je pense et avec différent anti spyware il me trouve plein de virus mais je peut pas les supprimer il me faut la clé d'activation donc pas de free trial et les autres anti spywate free ils ne me trouvent rien
merci quand même à tous je pense être sortit d'affaire j'ai trouvé 2 logiciel performant qui m'ont supprimer un bonne grosse liste de virus .
Si tu as 10 anti-spywares installés sur ton ordinateur, pas étonnant que ton ordinateur rame...
Quels sont les logiciels qui ont détectés des infections ? Peux-tu poster les rapports pour que je vois de quoi il s'agit stp ?
Quels sont les logiciels qui ont détectés des infections ? Peux-tu poster les rapports pour que je vois de quoi il s'agit stp ?
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
NN j'ai pas 10 antispyware j'en installe 1 puis je le désintalle et j'en installe un autre mais jamais 2 en même temps pour les rapport je n'ai rien
à pardon si j'ai trouvé
Start Date:August 08, 2009 at 07:29:23PM
End Date:August 08, 2009 at 07:42:44PM
Total Time:13 Mins 21 Secs
Detected Infections
Cookie.Tracking-Cookie
Details: A Tracking Cookie is any cookie that is installed on a computer to save and access various activities of the user. It may be used by web sites to identify returning visitors who have registered for special services; to monitor, measure, and scrutinize visitors' navigation and use of web site features. It can also count the number of visitors to web sites and allow web surfers to use virtual "shopping carts". All this information is saved for future target advertising and marketing campaigns by various internet Advertising and Marketing companies. Though these cookies do not pose immediate threats but they can be misused to capture confidential information like user names and passwords.
Status:No Action taken
Category: Tracking Cookie
Infected Cookies
C:\Documents and Settings\Fabien\Cookies\fabien@xiti[1].txt
Adware.Casino-Tropez
Details: Malware is a malicious program that is developed to seriously harm and damage the targeted system and may be installed on it without the knowledge or consent of the user. It can change system settings, corrupt the registry and destroy personal data. The Programs that cannot be classified in other categories or carry more than one traits which belong to different categories have been categorized under this categories.
Status:No Action taken
Category: Malware (General)
Infected registry keys/values detected
hkey_local_machine\software\ptech\
hkey_local_machine\software\ptech\ptserialnum\
PSW-Stealer.Nilage (General Components)
Details: A Password Stealer is a password cracking program that steals encrypted passwords on a computer or a computer network. Though this program may have legitimate uses, it is often misused by people to gain unauthorized access to the victim’s PC or network to steal login credentials for financial accounts and institutions. It usually runs in stealth mode to avoid detection and can pose serious security and privacy threats. Users are advised to remove this program from their system immediately upon detection.
Status:No Action taken
Category: PSW-Stealer
Infected registry keys/values detected
hkey_local_machine\system\currentcontrolset\services\6to4\parameters\
hkey_local_machine\system\currentcontrolset\services\6to4\parameters\servicedll\
Malware (General Components)
Details: Malware is a malicious program that is developed to seriously harm and damage the targeted system and may be installed on it without the knowledge or consent of the user. It can change system settings, corrupt the registry and destroy personal data. The Programs that cannot be classified in other categories or carry more than one traits which belong to different categories have been categorized under this categories.
Status:No Action taken
Category: Malware (General)
Infected registry keys/values detected
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\05p.co
m\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\198732
4.com\www\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\awmdab
est.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\blazef
ind.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\clicks
pring.net\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\crazyw
innings.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\elitem
ediagroup.net\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\flings
tone.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\master
69.biz\www\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\media-
motor.net\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\mt-dow
nload.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\needed
ware.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\scoobi
doo.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\search
barcash.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\search
miracle.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\sgrunt
.biz\www\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\skoobi
doo.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\slotch
.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\slotch
bar.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\topcon
verting.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\windup
dates.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoo
lbar.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\ysbweb
.com\
hkey_current_user\software\microsoft\append\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\awmda
best.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\blaze
find.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\click
spring.net\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\crazy
winnings.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\mt-do
wnload.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\scoob
idoo.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\searc
hmiracle.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\skoob
idoo.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\slotc
h.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\slotc
hbar.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\topco
nverting.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\windu
pdates.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxto
olbar.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\ysbwe
b.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\ranges\range1
\:range\
Trojan.StartPage.ig
Details: A Trojan is a program that disguises itself to be a useful program, but actually performs some illicit activity when it is run. Trojans are installed under forged or deceptive masquerades such as a joke program, a cute animation or an obscene image or may be even sent bundled with software. This program permits the unauthorized collection, distortion, or obliteration of data and renders the system more vulnerable as it may track the user's password information, cause damage to user’s data or damage other programs installed on the infected system. It can also pose security and privacy threats to one’s system, needless to mention the damage it can cause to the important data and installed programs.
Status:No Action taken
Category: Trojan
Infected registry keys/values detected
hkey_current_user\software\microsoft\internet explorer\main\default_search_url\https://www.microsoft.com/fr-fr/
com/isapi/redir.dll?prd=ie&ar=iesearch\http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome\1\
RCS.RealVNC
Details: A Remote Control Software is a network program that is used by administrators to control computers in a network from a remote location. Though not harmful in itself but if used with malicious intent, such programs may cause damage to system files and other data. Hence, users are advised to remove this program from their system immediately upon detection.
Status:No Action taken
Category: RemoteControlSoftware
Infected registry keys/values detected
hkey_current_user\software\realvnc\winvnc4\
Start Date:August 08, 2009 at 07:43:48PM
End Date:August 08, 2009 at 07:46:50PM
Total Time:3 Mins 2 Secs
Detected Infections
Cookie.Tracking-Cookie
Details: A Tracking Cookie is any cookie that is installed on a computer to save and access various activities of the user. It may be used by web sites to identify returning visitors who have registered for special services; to monitor, measure, and scrutinize visitors' navigation and use of web site features. It can also count the number of visitors to web sites and allow web surfers to use virtual "shopping carts". All this information is saved for future target advertising and marketing campaigns by various internet Advertising and Marketing companies. Though these cookies do not pose immediate threats but they can be misused to capture confidential information like user names and passwords.
Status:Removed
Category: Tracking Cookie
Infected Cookies
C:\Documents and Settings\Fabien\Cookies\fabien@xiti[1].txt
Adware.Casino-Tropez
Details: Malware is a malicious program that is developed to seriously harm and damage the targeted system and may be installed on it without the knowledge or consent of the user. It can change system settings, corrupt the registry and destroy personal data. The Programs that cannot be classified in other categories or carry more than one traits which belong to different categories have been categorized under this categories.
Status:Removed
Category: Malware (General)
Infected registry keys/values detected
hkey_local_machine\software\ptech\
hkey_local_machine\software\ptech\ptserialnum\
PSW-Stealer.Nilage (General Components)
Details: A Password Stealer is a password cracking program that steals encrypted passwords on a computer or a computer network. Though this program may have legitimate uses, it is often misused by people to gain unauthorized access to the victim’s PC or network to steal login credentials for financial accounts and institutions. It usually runs in stealth mode to avoid detection and can pose serious security and privacy threats. Users are advised to remove this program from their system immediately upon detection.
Status:Removed
Category: PSW-Stealer
Infected registry keys/values detected
hkey_local_machine\system\currentcontrolset\services\6to4\parameters\
hkey_local_machine\system\currentcontrolset\services\6to4\parameters\servicedll\
Malware (General Components)
Details: Malware is a malicious program that is developed to seriously harm and damage the targeted system and may be installed on it without the knowledge or consent of the user. It can change system settings, corrupt the registry and destroy personal data. The Programs that cannot be classified in other categories or carry more than one traits which belong to different categories have been categorized under this categories.
Status:Removed
Category: Malware (General)
Infected registry keys/values detected
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\05p.co
m\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\198732
4.com\www\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\awmdab
est.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\blazef
ind.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\clicks
pring.net\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\crazyw
innings.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\elitem
ediagroup.net\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\flings
tone.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\master
69.biz\www\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\media-
motor.net\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\mt-dow
nload.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\needed
ware.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\scoobi
doo.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\search
barcash.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\search
miracle.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\sgrunt
.biz\www\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\skoobi
doo.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\slotch
.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\slotch
bar.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\topcon
verting.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\windup
dates.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoo
lbar.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\ysbweb
.com\
hkey_current_user\software\microsoft\append\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\awmda
best.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\blaze
find.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\click
spring.net\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\crazy
winnings.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\mt-do
wnload.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\scoob
idoo.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\searc
hmiracle.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\skoob
idoo.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\slotc
h.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\slotc
hbar.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\topco
nverting.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\windu
pdates.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxto
olbar.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\ysbwe
b.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\ranges\range1
\:range\
Trojan.StartPage.ig
Details: A Trojan is a program that disguises itself to be a useful program, but actually performs some illicit activity when it is run. Trojans are installed under forged or deceptive masquerades such as a joke program, a cute animation or an obscene image or may be even sent bundled with software. This program permits the unauthorized collection, distortion, or obliteration of data and renders the system more vulnerable as it may track the user's password information, cause damage to user’s data or damage other programs installed on the infected system. It can also pose security and privacy threats to one’s system, needless to mention the damage it can cause to the important data and installed programs.
Status:Removed
Category: Trojan
Infected registry keys/values detected
hkey_current_user\software\microsoft\internet explorer\main\default_search_url\https://www.microsoft.com/fr-fr/
com/isapi/redir.dll?prd=ie&ar=iesearch\http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome\1\
RCS.RealVNC
Details: A Remote Control Software is a network program that is used by administrators to control computers in a network from a remote location. Though not harmful in itself but if used with malicious intent, such programs may cause damage to system files and other data. Hence, users are advised to remove this program from their system immediately upon detection.
Status:Removed
Category: RemoteControlSoftware
Infected registry keys/values detected
hkey_current_user\software\realvnc\winvnc4\
Start Date:August 08, 2009 at 07:48:23PM
End Date:August 08, 2009 at 07:48:33PM
Total Time:0 Mins 10 Secs
No Spywares Detected
Start Date:August 08, 2009 at 07:50:45PM
End Date:August 08, 2009 at 07:53:36PM
Total Time:2 Mins 51 Secs
No Spywares Detected
Start Date:August 08, 2009 at 07:29:23PM
End Date:August 08, 2009 at 07:42:44PM
Total Time:13 Mins 21 Secs
Detected Infections
Cookie.Tracking-Cookie
Details: A Tracking Cookie is any cookie that is installed on a computer to save and access various activities of the user. It may be used by web sites to identify returning visitors who have registered for special services; to monitor, measure, and scrutinize visitors' navigation and use of web site features. It can also count the number of visitors to web sites and allow web surfers to use virtual "shopping carts". All this information is saved for future target advertising and marketing campaigns by various internet Advertising and Marketing companies. Though these cookies do not pose immediate threats but they can be misused to capture confidential information like user names and passwords.
Status:No Action taken
Category: Tracking Cookie
Infected Cookies
C:\Documents and Settings\Fabien\Cookies\fabien@xiti[1].txt
Adware.Casino-Tropez
Details: Malware is a malicious program that is developed to seriously harm and damage the targeted system and may be installed on it without the knowledge or consent of the user. It can change system settings, corrupt the registry and destroy personal data. The Programs that cannot be classified in other categories or carry more than one traits which belong to different categories have been categorized under this categories.
Status:No Action taken
Category: Malware (General)
Infected registry keys/values detected
hkey_local_machine\software\ptech\
hkey_local_machine\software\ptech\ptserialnum\
PSW-Stealer.Nilage (General Components)
Details: A Password Stealer is a password cracking program that steals encrypted passwords on a computer or a computer network. Though this program may have legitimate uses, it is often misused by people to gain unauthorized access to the victim’s PC or network to steal login credentials for financial accounts and institutions. It usually runs in stealth mode to avoid detection and can pose serious security and privacy threats. Users are advised to remove this program from their system immediately upon detection.
Status:No Action taken
Category: PSW-Stealer
Infected registry keys/values detected
hkey_local_machine\system\currentcontrolset\services\6to4\parameters\
hkey_local_machine\system\currentcontrolset\services\6to4\parameters\servicedll\
Malware (General Components)
Details: Malware is a malicious program that is developed to seriously harm and damage the targeted system and may be installed on it without the knowledge or consent of the user. It can change system settings, corrupt the registry and destroy personal data. The Programs that cannot be classified in other categories or carry more than one traits which belong to different categories have been categorized under this categories.
Status:No Action taken
Category: Malware (General)
Infected registry keys/values detected
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\05p.co
m\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\198732
4.com\www\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\awmdab
est.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\blazef
ind.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\clicks
pring.net\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\crazyw
innings.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\elitem
ediagroup.net\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\flings
tone.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\master
69.biz\www\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\media-
motor.net\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\mt-dow
nload.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\needed
ware.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\scoobi
doo.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\search
barcash.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\search
miracle.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\sgrunt
.biz\www\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\skoobi
doo.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\slotch
.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\slotch
bar.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\topcon
verting.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\windup
dates.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoo
lbar.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\ysbweb
.com\
hkey_current_user\software\microsoft\append\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\awmda
best.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\blaze
find.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\click
spring.net\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\crazy
winnings.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\mt-do
wnload.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\scoob
idoo.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\searc
hmiracle.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\skoob
idoo.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\slotc
h.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\slotc
hbar.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\topco
nverting.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\windu
pdates.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxto
olbar.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\ysbwe
b.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\ranges\range1
\:range\
Trojan.StartPage.ig
Details: A Trojan is a program that disguises itself to be a useful program, but actually performs some illicit activity when it is run. Trojans are installed under forged or deceptive masquerades such as a joke program, a cute animation or an obscene image or may be even sent bundled with software. This program permits the unauthorized collection, distortion, or obliteration of data and renders the system more vulnerable as it may track the user's password information, cause damage to user’s data or damage other programs installed on the infected system. It can also pose security and privacy threats to one’s system, needless to mention the damage it can cause to the important data and installed programs.
Status:No Action taken
Category: Trojan
Infected registry keys/values detected
hkey_current_user\software\microsoft\internet explorer\main\default_search_url\https://www.microsoft.com/fr-fr/
com/isapi/redir.dll?prd=ie&ar=iesearch\http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome\1\
RCS.RealVNC
Details: A Remote Control Software is a network program that is used by administrators to control computers in a network from a remote location. Though not harmful in itself but if used with malicious intent, such programs may cause damage to system files and other data. Hence, users are advised to remove this program from their system immediately upon detection.
Status:No Action taken
Category: RemoteControlSoftware
Infected registry keys/values detected
hkey_current_user\software\realvnc\winvnc4\
Start Date:August 08, 2009 at 07:43:48PM
End Date:August 08, 2009 at 07:46:50PM
Total Time:3 Mins 2 Secs
Detected Infections
Cookie.Tracking-Cookie
Details: A Tracking Cookie is any cookie that is installed on a computer to save and access various activities of the user. It may be used by web sites to identify returning visitors who have registered for special services; to monitor, measure, and scrutinize visitors' navigation and use of web site features. It can also count the number of visitors to web sites and allow web surfers to use virtual "shopping carts". All this information is saved for future target advertising and marketing campaigns by various internet Advertising and Marketing companies. Though these cookies do not pose immediate threats but they can be misused to capture confidential information like user names and passwords.
Status:Removed
Category: Tracking Cookie
Infected Cookies
C:\Documents and Settings\Fabien\Cookies\fabien@xiti[1].txt
Adware.Casino-Tropez
Details: Malware is a malicious program that is developed to seriously harm and damage the targeted system and may be installed on it without the knowledge or consent of the user. It can change system settings, corrupt the registry and destroy personal data. The Programs that cannot be classified in other categories or carry more than one traits which belong to different categories have been categorized under this categories.
Status:Removed
Category: Malware (General)
Infected registry keys/values detected
hkey_local_machine\software\ptech\
hkey_local_machine\software\ptech\ptserialnum\
PSW-Stealer.Nilage (General Components)
Details: A Password Stealer is a password cracking program that steals encrypted passwords on a computer or a computer network. Though this program may have legitimate uses, it is often misused by people to gain unauthorized access to the victim’s PC or network to steal login credentials for financial accounts and institutions. It usually runs in stealth mode to avoid detection and can pose serious security and privacy threats. Users are advised to remove this program from their system immediately upon detection.
Status:Removed
Category: PSW-Stealer
Infected registry keys/values detected
hkey_local_machine\system\currentcontrolset\services\6to4\parameters\
hkey_local_machine\system\currentcontrolset\services\6to4\parameters\servicedll\
Malware (General Components)
Details: Malware is a malicious program that is developed to seriously harm and damage the targeted system and may be installed on it without the knowledge or consent of the user. It can change system settings, corrupt the registry and destroy personal data. The Programs that cannot be classified in other categories or carry more than one traits which belong to different categories have been categorized under this categories.
Status:Removed
Category: Malware (General)
Infected registry keys/values detected
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\05p.co
m\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\198732
4.com\www\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\awmdab
est.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\blazef
ind.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\clicks
pring.net\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\crazyw
innings.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\elitem
ediagroup.net\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\flings
tone.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\master
69.biz\www\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\media-
motor.net\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\mt-dow
nload.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\needed
ware.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\scoobi
doo.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\search
barcash.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\search
miracle.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\sgrunt
.biz\www\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\skoobi
doo.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\slotch
.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\slotch
bar.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\topcon
verting.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\windup
dates.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoo
lbar.com\
hkey_current_user\software\microsoft\windows\currentversion\internet settings\zonemap\domains\ysbweb
.com\
hkey_current_user\software\microsoft\append\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\awmda
best.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\blaze
find.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\click
spring.net\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\crazy
winnings.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\mt-do
wnload.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\scoob
idoo.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\searc
hmiracle.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\skoob
idoo.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\slotc
h.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\slotc
hbar.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\topco
nverting.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\windu
pdates.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxto
olbar.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\ysbwe
b.com\
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\ranges\range1
\:range\
Trojan.StartPage.ig
Details: A Trojan is a program that disguises itself to be a useful program, but actually performs some illicit activity when it is run. Trojans are installed under forged or deceptive masquerades such as a joke program, a cute animation or an obscene image or may be even sent bundled with software. This program permits the unauthorized collection, distortion, or obliteration of data and renders the system more vulnerable as it may track the user's password information, cause damage to user’s data or damage other programs installed on the infected system. It can also pose security and privacy threats to one’s system, needless to mention the damage it can cause to the important data and installed programs.
Status:Removed
Category: Trojan
Infected registry keys/values detected
hkey_current_user\software\microsoft\internet explorer\main\default_search_url\https://www.microsoft.com/fr-fr/
com/isapi/redir.dll?prd=ie&ar=iesearch\http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome\1\
RCS.RealVNC
Details: A Remote Control Software is a network program that is used by administrators to control computers in a network from a remote location. Though not harmful in itself but if used with malicious intent, such programs may cause damage to system files and other data. Hence, users are advised to remove this program from their system immediately upon detection.
Status:Removed
Category: RemoteControlSoftware
Infected registry keys/values detected
hkey_current_user\software\realvnc\winvnc4\
Start Date:August 08, 2009 at 07:48:23PM
End Date:August 08, 2009 at 07:48:33PM
Total Time:0 Mins 10 Secs
No Spywares Detected
Start Date:August 08, 2009 at 07:50:45PM
End Date:August 08, 2009 at 07:53:36PM
Total Time:2 Mins 51 Secs
No Spywares Detected